Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zope zope vulnerabilities and exploits
(subscribe to this query)
7.2
CVSSv3
CVE-2021-32811
Zope is an open-source web application server. Zope versions prior to versions 4.6.3 and 5.3 have a remote code execution security issue. In order to be affected, one must use Python 3 for one's Zope deployment, run Zope 4 below version 4.6.3 or Zope 5 below version 5.3, and...
Zope Accesscontrol
Zope Zope
7.2
CVSSv3
CVE-2021-32807
The module `AccessControl` defines security policies for Python code used in restricted code within Zope applications. Restricted code is any code that resides in Zope's object database, such as the contents of `Script (Python)` objects. The policies defined in `AccessContro...
Zope Accesscontrol
6.5
CVSSv3
CVE-2021-21336
Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 there is an information disclosure vulnerability - everyone can list the names of roles defined in the ZODB Role Manager plugin if t...
Zope Products.pluggableauthservice
Plone Plone
6.1
CVSSv3
CVE-2021-33507
Zope Products.CMFCore prior to 2.5.1 and Products.PluggableAuthService prior to 2.6.2, as used in Plone up to and including 5.2.4 and other products, allow Reflected XSS.
Plone Plone
Zope Zope
6.1
CVSSv3
CVE-2021-21337
Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 there is an open redirect vulnerability. A maliciously crafted link to the login form and login functionality could redirect the bro...
Zope Products.pluggableauthservice
6.1
CVSSv3
CVE-2013-7062
Multiple cross-site scripting (XSS) vulnerabilities in Zope, as used in Plone 3.3.x up to and including 3.3.6, 4.0.x up to and including 4.0.9, 4.1.x up to and including 4.1.6, 4.2.x up to and including 4.2.7, and 4.3 up to and including 4.3.2, allow remote malicious users to inj...
Plone Plone
6.1
CVSSv3
CVE-2011-4924
Cross-site scripting (XSS) vulnerability in Zope 2.8.x prior to 2.8.12, 2.9.x prior to 2.9.12, 2.10.x prior to 2.10.11, 2.11.x prior to 2.11.6, and 2.12.x prior to 2.12.3, 3.1.1 up to and including 3.4.1. allows remote malicious users to inject arbitrary web script or HTML via ve...
Zope Zope
6.1
CVSSv3
CVE-2009-5145
Cross-site scripting (XSS) vulnerability in ZMI pages that use the manage_tabs_message in Zope 2.11.4, 2.11.2, 2.10.9, 2.10.7, 2.10.6, 2.10.5, 2.10.4, 2.10.2, 2.10.1, 2.12.
Zope Zope 2.11.2
Zope Zope 2.10.4
Zope Zope 2.10.1
Zope Zope 2.10.9
Zope Zope 2.10.7
Zope Zope 2.10.6
Zope Zope 2.10.5
Zope Zope 2.11.4
Zope Zope 2.10.2
Zope Zope 2.12.0
6.1
CVSSv3
CVE-2016-7147
Cross-site scripting (XSS) vulnerability in the manage_findResult component in the search feature in Zope ZMI in Plone prior to 4.3.12 and 5.x prior to 5.0.7 allows remote malicious users to inject arbitrary web script or HTML via vectors involving double quotes, as demonstrated ...
Plone Plone 5.1
Plone Plone 5.0.6
Plone Plone 5.0
Plone Plone 4.3.9
Plone Plone 4.3.10
Plone Plone 3.3.6
Plone Plone 4.0.5
Plone Plone 4.1.5
Plone Plone 4.1.6
Plone Plone 4.2.7
Plone Plone 4.0.3
Plone Plone 3.3.2
Plone Plone 3.3.3
Plone Plone 5.0.5
Plone Plone 5.0.4
Plone Plone 4.3.3
Plone Plone 4.3.11
Plone Plone 4.3
Plone Plone 4.0.4
Plone Plone 4.1
Plone Plone 4.2
Plone Plone 4.2.1
5.4
CVSSv3
CVE-2023-42458
Zope is an open-source web application server. Prior to versions 4.8.10 and 5.8.5, there is a stored cross site scripting vulnerability for SVG images. Note that an image tag with an SVG image as source is never vulnerable, even when the SVG image contains malicious code. To expl...
Zope Zope
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5248
CVE-2024-3110
CVE-2024-5552
CVE-2024-29415
HTML injection
CVE-2024-3095
TCP
type confusion
CVE-2024-1800
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »